CVE-2022-28810
Last modified
CVE-2022-28810 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. CISA has confirmed active exploitation in the wild. EPSS estimates a 70.42% chance of exploitation in the next 30 days.
Description
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Adselfservice Plus | < 6.1 |
| Zohocorp | Manageengine Adselfservice Plus | 6.1 |
References
- https://packetstormsecurity.com/files/166816/ManageEngine-ADSelfService-Plus-Custom-Script-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/rapid7/metasploit-framework/pull/16475Exploit, Patch, Third Party Advisory
- https://www.manageengine.com/products/self-service-password/kb/cve-2022-28810.htmlPatch, Vendor Advisory
- https://www.rapid7.com/blog/post/2022/04/14/cve-2022-28810-manageengine-adselfservice-plus-authenticated-command-execution-fixed/Exploit, Patch, Technical Description, Third Party Advisory
- https://packetstormsecurity.com/files/166816/ManageEngine-ADSelfService-Plus-Custom-Script-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/rapid7/metasploit-framework/pull/16475Exploit, Patch, Third Party Advisory
- https://www.manageengine.com/products/self-service-password/kb/cve-2022-28810.htmlPatch, Vendor Advisory
- https://www.rapid7.com/blog/post/2022/04/14/cve-2022-28810-manageengine-adselfservice-plus-authenticated-command-execution-fixed/Exploit, Patch, Technical Description, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-28810US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-28810?
How severe is CVE-2022-28810?
How do I fix CVE-2022-28810?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-28805singlevar in lparser.c in Lua from (including) 5.4.0 up to (…9.1
- CVE-2022-28806An issue was discovered on certain Fujitsu LIEFBOOK devices …7.8
- CVE-2022-28807An issue was discovered in Open Design Alliance Drawings SDK…7.8
- CVE-2022-28808An issue was discovered in Open Design Alliance Drawings SDK…7.8
- CVE-2022-28809An issue was discovered in Open Design Alliance Drawings SDK…7.8
- CVE-2022-2881The underlying bug might cause read past end of the buffer a…8.2
- CVE-2022-28811In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Par…9.8
- CVE-2022-28812In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Par…9.8
- CVE-2022-28813In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Par…7.5
- CVE-2022-28814Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park S…9.8
- CVE-2022-28815In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Par…2.7
- CVE-2022-28816In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Par…6.1
Are you affected by CVE-2022-28810?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
